From feb0daf81d888e9160f9f94502de09b66f2a63fd Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 21 Jun 2020 17:50:24 +0100 Subject: gentoo resync : 21.06.2020 --- metadata/glsa/glsa-202006-23.xml | 50 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 metadata/glsa/glsa-202006-23.xml (limited to 'metadata/glsa/glsa-202006-23.xml') diff --git a/metadata/glsa/glsa-202006-23.xml b/metadata/glsa/glsa-202006-23.xml new file mode 100644 index 000000000000..7fb7e375cbc8 --- /dev/null +++ b/metadata/glsa/glsa-202006-23.xml @@ -0,0 +1,50 @@ + + + + Cyrus IMAP Server: Access restriction bypass + An error in Cyrus IMAP Server allows mailboxes to be created with + administrative privileges. + + cyrusimap + 2020-06-15 + 2020-06-15 + 703630 + remote + + + 3.0.13 + 3.0.13 + + + +

The Cyrus IMAP Server is an efficient, highly-scalable IMAP e-mail + server. +

+
+ +

An issue was discovered in Cyrus IMAP Server where sieve script + uploading is excessively trusted. +

+
+ +

A user can use a sieve script to create any mailbox with administrator + privileges. +

+
+ +

Disable sieve script uploading until the upgrade is complete.

+
+ +

All Cyrus IMAP Server users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-mail/cyrus-imapd-3.0.13" + +
+ + CVE-2019-19783 + + sam_c + sam_c +
-- cgit v1.2.3